Web Hack List

Collected research

Robust Defenses for Cross-Site Request Forgery (Login CSRF & the Origin header)

CCS 2008 paper introducing login CSRF, where a forged request to the login form signs the victim in as the attacker so their activity accrues to the attacker's account. It dissects secret-token, Referer and custom-header defences, and measures Referer suppression over 283,945 ad impressions: heavy on HTTP, negligible on HTTPS. Proposes the Origin header, with browser and Apache patches.

Record

Researcher
Adam Barth, Collin Jackson and John C. Mitchell
Published by
seclab.stanford.edu
Format
Whitepaper
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Barth, Collin Jackson and John C. Mitchell, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .